Deprecated: Deprecated in Query Context

Deprecated when used in query context, meant for use in parsers only. For uses in queries please use the lower() function. Lower-cases the contents of either or both of the field names or values of a string field.

Function Summary
Signaturelowercase(field, [include], [locale])
Output DataZero or One Event per Input Event
Function TypeTransformation
Parameters for lowercase()
ParameterTypeInterpreted TypeRequiredDefault ValueDescription
field[a]array of stringsarray of fieldnamesrequired   The name of the input field or fields (in []) to lowercase. Use the special value as the only field * for ALL fields. When in this mode only the lower-cased fields remain.
includestringfixed valuesoptional[b] values What to lowercase.
    Values
    bothConvert both the values and field names to lowercase
    fieldsConvert the field names to lowercase
    valuesConvert the values of the fields to lowercase
localestringstringoptional[b]   The name of the locale to use, as ISO 639 language and an optional ISO 3166 country, such as da, da_DK or en_US. When not specified, uses the system locale.

[a] The parameter name field can be omitted.

[b] Optional parameters use their default value unless explicitly set.

Hide omitted argument names for this function

Show omitted argument names for this function

lowercase() Syntax Examples

With an event with a field Bar=CONTENTS, you get contents in the Bar field:

logscale
lowercase("Bar")

With an event with a field BAR=CONTENTS, you get CONTENTS in the bar field, while BAR is still CONTENTS.

logscale
lowercase("BaR", include="values")

With an event with a field BAR=CONTENTS, you get contents in the bar field, while BAR is still CONTENTS.

logscale
lowercase(field=["foo","bar"], include="both")

With an event with a field BAR=CONTENTS, you get contents in the bar field, while BAR is no longer present.

logscale
lowercase(field="*", include="both")